Fox Kitten is an Iranian state-sponsored APT that combines intelligence collection for the IRGC with a profit-driven business selling access to ransomware affiliates. It has repeatedly exploited internet-facing VPN and firewall devices worldwide, using tools and custom malware such as HanifNet, HXLibrary, NeoExpressRAT, and Pay2Key to maintain access and support extortion operations. #FoxKitten #IRGC #HanifNet #HXLibrary #NeoExpressRAT #Pay2Key
Keypoints
- Fox Kitten is a state-sponsored Iranian threat actor active since at least 2017 and tracked under aliases including Pioneer Kitten, UNC757, Parisite, RUBIDIUM, and Lemon Sandstorm.
- The group operates in a dual role: espionage for Iranian state intelligence objectives and monetizing access by selling compromised networks to ransomware affiliates.
- Its primary targets are exposed perimeter devices such as VPN concentrators, firewalls, and remote access gateways, rather than a single industry.
- Fox Kitten has targeted organizations across the Middle East, North Africa, Europe, Australia, and North America, with documented victims in the United States.
- The group rapidly weaponizes newly disclosed vulnerabilities in products from Pulse Secure, Citrix, F5, Palo Alto, and Check Point for initial access.
- Post-compromise activity includes credential theft, tunneling-based persistence, lateral movement, cloud and messaging collection, and defense evasion through masquerading and timestomping.
- Campaigns linked to the group include the Pay2Key operation against Israeli organizations and a 2024 ransomware facilitation campaign involving NoEscape, Ransomhouse, and ALPHV (BlackCat).
MITRE Techniques
- [T1190 ] Exploit Public-Facing Application â Used to gain initial access by exploiting internet-facing VPN and firewall appliances, including newly disclosed CVEs (âthe group has demonstrated a pattern of rapidly weaponizing newly disclosed CVEs in widely deployed VPN and firewall productsâ).
- [T1133 ] External Remote Services â Used against exposed VPNs and remote access gateways to enter victim environments (âtargeting⌠VPN concentrators, firewalls, and remote access gatewaysâ).
- [T1110 ] Brute Force â Used as a secondary access path against RDP credentials (âuses brute force against RDP credentials as a secondary access pathâ).
- [T1059.001 ] Command and Scripting Interpreter: PowerShell â Used extensively for credential access and payload staging (âPowerShell is used extensively for credential access and payload stagingâ).
- [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell â Used for account manipulation tasks (âWindows Command Shell (cmd.exe) has been observed for account manipulation tasksâ).
- [T1059 ] Command and Scripting Interpreter: Perl Reverse Shell â Used for C2 communication in some intrusions (âthe group also deploys a Perl reverse shell for C2 communicationâ).
- [T1569.002 ] System Services: Service Execution â Used PsExec for remote command execution across the network (âuses PsExec for remote command execution across the networkâ).
- [T1505.003 ] Server Software Component: Web Shell â Deployed web shells on compromised servers for persistence (âWeb shells ⌠deployed on compromised serversâ).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Created scheduled tasks to preserve access (âScheduled Tasks named to masquerade as legitimate system tasksâ).
- [T1136.001 ] Create Account: Local Account â Created local administrator accounts for long-term access (âLocal administrator accounts created with elevated privilegesâ).
- [T1546.008 ] Event Triggered Execution: Accessibility Features â Abused Sticky Keys to launch a command prompt at login (âSticky Keys abuse ⌠replacing accessibility executablesâ).
- [T1027.010 ] Obfuscated Files or Information: Command Obfuscation â Used Base64 encoding to obscure scripts and payloads (âBase64 encoding of scripts and payloadsâ).
- [T1027.013 ] Obfuscated Files or Information: Encrypted/Encoded File â Used encoded payloads to hinder analysis (âBase64 encoding of scripts and payloadsâ).
- [T1036.004 ] Masquerading: Masquerade Task or Service â Named tasks to look legitimate (âScheduled Tasks named to masquerade as legitimate system tasksâ).
- [T1036.005 ] Masquerading: Match Legitimate Resource Name or Location â Renamed binaries and config files to blend in (ânaming binaries svhost and config files dllhostâ).
- [T1070.006 ] Indicator Removal: Timestomp â Altered file metadata to hide artifacts (âperforms timestomping via China Chopperâ).
- [T1003.001 ] OS Credential Dumping: LSASS Memory â Used prodump to dump credentials from LSASS (âuses prodump ⌠to dump credentials from LSASS memoryâ).
- [T1003.003 ] OS Credential Dumping: NTDS â Used Volume Shadow Copy to extract NTDS.dit for offline AD harvesting (âleverages Volume Shadow Copy to extract NTDS.ditâ).
- [T1555.005 ] Credentials from Password Stores: Password Managers â Read KeePass databases to steal stored secrets (âreading KeePass databases using targeted scriptsâ).
- [T1552.001 ] Unsecured Credentials: Credentials In Files â Accessed registry hives and other files for stored credentials (âaccessing ntuser.dat and UserClass.dat registry hivesâ).
- [T1078 ] Valid Accounts â Leveraged stolen credentials for RDP, SMB, SSH, and VNC lateral movement (âwith valid stolen credentialsâ).
- [T1087.001 ] Account Discovery: Local Account â Enumerated local accounts during reconnaissance (âenumerate Active Directory service accountsâ).
- [T1087.002 ] Account Discovery: Domain Account â Enumerated domain accounts and AD service accounts (âenumerate Active Directory service accountsâ).
- [T1046 ] Network Service Discovery â Used Nmap and Angry IP Scanner for network discovery (âNmap and Angry IP Scanner for network discoveryâ).
- [T1018 ] Remote System Discovery â Identified internal systems and assets (âread Chrome browser bookmarks to identify internal resources and assetsâ).
- [T1083 ] File and Directory Discovery â Used WizTree for file and directory enumeration (âWizTree for file and directory enumerationâ).
- [T1012 ] Query Registry â Accessed registry hives to recover credentials (âaccessing ntuser.dat and UserClass.dat registry hivesâ).
- [T1217 ] Browser Information Discovery â Read Chrome bookmarks to find internal resources (âreads Chrome browser bookmarksâ).
- [T1021.001 ] Remote Services: Remote Desktop Protocol â Used RDP for lateral movement (âLateral movement relies heavily on RDPâ).
- [T1021.002 ] Remote Services: SMB/Windows Admin Shares â Used SMB/admin shares to move laterally (âSMB/Windows Admin Sharesâ).
- [T1021.004 ] Remote Services: SSH â Used PuTTY and Plink for SSH-based movement (âSSH (via PuTTY and Plink)â).
- [T1021.005 ] Remote Services: VNC â Deployed TightVNC for remote access (âVNC (TightVNC server and client deployed on endpoints)â).
- [T1210 ] Exploitation of Remote Services â Used compromised services and RDP/remote access paths to expand control (âuses brute force against RDP credentialsâ and exploits remote access infrastructure).
- [T1570 ] Lateral Tool Transfer â Used PsExec and other tools across hosts (âPsExec is used for remote service execution across compromised hostsâ).
- [T1005 ] Data from Local System â Collected internal documents, email archives, and local files (âtargets credentials, internal documents, email archivesâ).
- [T1039 ] Data from Network Shared Drive â Gathered data from network shares (âData from network sharesâ).
- [T1530 ] Data from Cloud Storage â Collected contents from cloud storage instances (âcloud storage contentsâ).
- [T1213.005 ] Data from Information Repositories: Messaging Applications â Accessed Microsoft Teams messages for intelligence (âaccesses Microsoft Teams to mine communicationsâ).
- [T1560.001 ] Archive Collected Data: Archive via Utility â Used 7-Zip to compress staged data before exfiltration (âstaged using 7-Zip for compressionâ).
- [T1572 ] Protocol Tunneling â Used reverse proxies and tunneling tools to create outbound tunnels (âestablish outbound tunnels from victim environmentsâ).
- [T1090 ] Proxy â Used FRPC, ngrok, Glider Proxy, ReverseSocks5, Chisel, and MeshCentral as proxying tools (âreverse proxy toolsâ).
- [T1102 ] Web Service â Used AWS-hosted infrastructure and social platforms for communication (âAmazon Web Services has been observed as C2 hosting infrastructureâ; âKeyBase and Twitter accountsâ).
- [T1585 ] Establish Accounts â Used online accounts as part of operations (âKeyBase and Twitter accounts have also been usedâ).
- [T1585.001 ] Social Media Accounts â Used Twitter accounts for victim communication (âTwitter accounts have also been usedâ).
- [T1041 ] Exfiltration Over C2 Channel â Exfiltrated data through the same C2/tunneled infrastructure (âprior to exfiltrationâ).
- [T1486 ] Data Encrypted for Impact â Deployed Pay2Key ransomware against Israeli organizations (âdeployed the custom Pay2Key ransomwareâ).
- [T1489 ] Service Stop â Included service disruption as part of impact (âService Stopâ).
Indicators of Compromise
- [CVE ] exploited vulnerabilities in perimeter devices â CVE-2019-11510, CVE-2024-24919, and other 5 CVEs
- [Malware/Tool Names ] custom malware and tooling used by Fox Kitten â HanifNet, HXLibrary, and other 6 items
- [File Names ] persistence and credential theft artifacts â sethc.exe, utilman.exe, and other 2 items
- [Domain/Service Names ] tunneling, C2, and communication services â ngrok, Amazon Web Services, and other 5 items
- [Account Handles ] underground and communication identifiers â Br0k3r, xplfinder, and other 2 aliases
- [Threat Actors / Affiliates ] ransomware partners and related groups â NoEscape, ALPHV (BlackCat), and other 1 item
- [Tools ] reconnaissance, lateral movement, and proxy tools â Nmap, PsExec, and other 10 items
- [Web Shell Names ] persistence web shell variants â China Chopper, ChunkyTuna, and other 1 item
Read more: https://socradar.io/blog/dark-web-profile-fox-kitten/